Privileged Account Management (PAM)

Number:

1220-030-2017-002

Title:

Privileged Account Management (PAM)

Description

Request for Proposals

PROJECT DESCRIPTION

In order to manage the numerous business systems and related infrastructure, the City of Surrey makes heavy use of privileged administration and service accounts. The City believes these accounts represent a significant risk to the organization if not properly managed. Historically, the City has been able to manage the provisioning and use of the accounts through manual processes; however, the City is now too large to be able to ensure the processes are consistently reliable. As such, the City has identified Privileged Account Management as one of the top critical controls needed to improve its overall security posture.

HIGH LEVEL DESCRIPTION OF GOODS AND SERVICES REQUESTED

The City moving towards a “Consolidated Edge” topology in an effort to simplify its security architecture. As part of this effort, the City will be replacing its current privileged password manager and manual processes with a single privileged account management solution. The solution proposed must function within a segregated environment that has isolated security zones (both north/south and east west security zones) within a single logical instance, allowing the City to ensure all privileged accounts are appropriately managed in all securely zones from a single management platform. The proposed solution must also support PCI DSS 3.2 compliance.

Specifically, the City is seeking a solution that provides the following:

Privileged Account Management

Automated Account Checkout and Privilege Escalation

Robust Auditing

API Based Functionality and DevOps Integration

Single Pane of Glass Management

Training (On-site Instructor Lead or Classroom Based)

Implementation Support Services

INFORMATION MEETING

An information meeting will be hosted by the City Representative to discuss the City’s requirements under this RFP (the “Information Meeting”). While attendance is at the discretion of Proponent, Proponents who do not attend will be deemed to have attended the Information Meeting and to have received all of the information given at the Information Meeting. At the time of issuance of this RFP a meeting has been scheduled as follows:

Addenda
If the City determines that an amendment is required to this RFP, the City Representative will issue a written addendum by posting it on the BC Bid Website at www.bcbid.bc.ca (the “BC Bid Website”) and the City Website at www.surrey.ca (the “City Website”) that will form part of this RFP. It is the responsibility of Proponents to check the BC Bid Website and the City Website for addenda. The only way this RFP may be added to, or amended in any way, is by a formal written addendum. No other communication, whether written or oral, from any person will affect or modify the terms of this RFP or may be relied upon by any Proponent. By delivery of a Proposal, Proponent is deemed to have received, accepted and understood the entire RFP, including any and all addenda.

All inquiries related to this RFP should be directed in writing to the person named below.